Public, Private or NDA-Controlled: Choosing How to Share Information

Different review stages require different levels of disclosure. Learn what may be suitable for public, private or NDA-controlled sharing—and why some sensitive information should not be shared at all.

Prepare documents for controlled sharing

This starts a temporary private draft. It is not public, listed for sale or shared automatically.

An asset package can contain information with very different sensitivity levels. A short public description may be useful for discovery, while signed agreements, customer data, source code or detailed financial records may require restricted access—or may not be appropriate to share at all.

The safest starting point is not “upload everything”. It is to decide what each reviewer needs at the current stage and disclose only that information through an appropriate access route.

Key point: Public, private and NDA-controlled sharing are not quality ratings. They are different disclosure choices. The person sharing information must still have authority and a lawful basis to disclose it.

Four practical disclosure choices

Choice Typical purpose Main caution
Public Discovery and a high-level description Information may be copied, indexed, downloaded, quoted or redistributed.
Private Internal preparation or access limited to selected authorised users Private status does not cure unlawful collection or disclosure and does not remove security risk.
NDA-controlled Due diligence with identified recipients for a defined purpose An NDA creates contractual obligations but cannot guarantee recipient behaviour or authorise disclosure you had no right to make.
Do not share yet Highly sensitive, legally restricted or unnecessary material Some information should remain outside the package until professional review or a later transaction stage.

The appropriate choice can change as a transaction progresses. A public teaser may later be supplemented by a controlled evidence package, but publication should not be treated as the default.

Public sharing: disclose the minimum needed for discovery

Public information should help a prospective reviewer understand the general opportunity without exposing the underlying confidential evidence.

Depending on the asset, a public description might include:

  • a high-level asset or right category;
  • a non-confidential summary of the opportunity;
  • broad jurisdiction or region;
  • an anonymised or aggregated description;
  • a general lifecycle or review status;
  • the types of evidence available under controlled access; and
  • clear qualifications about what has and has not been independently reviewed.

Public content should normally avoid unnecessary disclosure of:

  • personal contact details and home addresses;
  • identification documents, signatures and dates of birth;
  • bank details and payment credentials;
  • unredacted contracts, invoices or court documents;
  • debtor, customer or employee names where disclosure is not justified;
  • confidential pricing, royalty rates or commercial terms;
  • account credentials, API keys and security information;
  • unpublished inventions, source code, algorithms or trade secrets;
  • health, criminal-offence or other specially protected personal data; and
  • statements that could misrepresent ownership, value, verification or transferability.

Once information is public, removing it later may not remove copies, screenshots, search results or material already received by third parties. Treat public disclosure as potentially irreversible.

Private sharing: useful for preparation, but not a legal shortcut

Keeping an asset package private can be appropriate while documents are collected, AI-assisted findings are reviewed and gaps are corrected.

Private access can reduce exposure, but the label private does not itself establish that:

  • the uploader had authority to obtain or upload the information;
  • every person with access is authorised;
  • personal-data processing has a lawful basis;
  • contractual confidentiality obligations permit the upload;
  • retention is necessary and proportionate;
  • the information is accurate or complete; or
  • the package can later be disclosed to a buyer or adviser.

Review workspace membership, recipient permissions and linked accounts. Remove access that is no longer required. Do not use a shared account as a substitute for identifying individual users and their roles.

NDA-controlled sharing: define the permitted purpose

An NDA is a legal contract that governs how specified confidential information may be used and disclosed. It can support due diligence by limiting access to identified recipients for a stated purpose.

An NDA may address:

  • which information is confidential;
  • the purpose for which it may be used;
  • who may receive it;
  • whether professional advisers, employees or contractors may access it;
  • the recipient's protection and security duties;
  • copying, download and onward-disclosure restrictions;
  • exclusions for information already known or lawfully public;
  • compelled disclosures to courts or authorities;
  • duration of confidentiality obligations;
  • return, deletion or destruction requirements;
  • governing law and dispute provisions; and
  • available remedies for breach.

UK Intellectual Property Office guidance recommends defining the permitted purpose precisely and considering which employees or professional advisers may need access. The suitable terms and duration depend on the information and transaction.

An NDA should be reviewed before sensitive information is released. A generic template may not address the asset, parties, jurisdictions or disclosure route involved.

What an NDA does not do

An NDA can reduce risk and create contractual remedies, but it does not:

  • prove that the disclosing party owns the information;
  • give the disclosing party authority it did not already have;
  • provide a lawful basis for personal-data processing by itself;
  • override third-party confidentiality duties;
  • remove intellectual-property or data-licensing restrictions;
  • guarantee that the recipient will comply;
  • prevent every legally required disclosure;
  • make already-public information secret again;
  • prevent information from being remembered or independently developed; or
  • replace technical access controls and careful recipient selection.

NDAs must not be used to obstruct lawful reporting, regulatory cooperation, protected disclosures or other rights that cannot legally be excluded. Professional advice may be needed about applicable exceptions and enforceability.

Personal data requires a separate sharing decision

Personal data should not be included merely because it appears in a source document. Before sharing it, identify:

  • the purpose of the disclosure;
  • the lawful basis relied on;
  • whether the recipient genuinely needs the information;
  • whether anonymised, aggregated or redacted information would be sufficient;
  • whether special-category or criminal-offence data is involved;
  • what privacy information must be provided;
  • applicable retention and deletion periods;
  • security and access requirements; and
  • whether an international transfer mechanism is required.

The UK Information Commissioner's Office describes data minimisation as keeping personal data adequate, relevant and limited to what is necessary for the stated purpose. An NDA does not replace this assessment.

Practical redaction may include removing signatures, identity numbers, personal addresses, bank details, unrelated correspondence and information about people who are not necessary to the review.

Confidential information and trade secrets need active protection

Confidential know-how and trade secrets can lose protection or commercial value if they are disclosed without appropriate safeguards. Public disclosure may also affect the ability to seek certain forms of registered protection.

Reasonable protection measures may include:

  • identifying the confidential material;
  • limiting access to people with a genuine need to know;
  • using NDAs and confidentiality clauses;
  • applying technical and organisational security controls;
  • separating high-level summaries from detailed evidence;
  • watermarking or otherwise identifying controlled copies where appropriate;
  • keeping access and disclosure records; and
  • responding promptly to suspected unauthorised access.

The European Commission's trade-secret guidance emphasises that trade-secret protection concerns information with commercial value that is kept confidential through appropriate measures. The exact protection and remedies depend on applicable law.

Use staged disclosure

A staged approach can provide useful information without opening the complete data room at the first contact.

Stage 1 — Public teaser

Share only enough non-confidential information to support discovery and an initial expression of interest.

Stage 2 — Selected access

Provide a more detailed summary to an identified and authorised recipient. Confirm identity, role, purpose and conflicts before access.

Stage 3 — NDA-controlled evidence

After the appropriate NDA is in place, provide the documents required for focused due diligence. Continue to minimise and redact information.

Stage 4 — Restricted specialist review

Give particularly sensitive legal, technical, financial or personal material only to recipients who genuinely require it, such as named advisers or specialist reviewers. Additional controls may be appropriate.

Stage 5 — Transaction disclosure

Share final transaction documents and completion information only through the agreed process and subject to applicable legal, regulatory and contractual requirements.

Each stage should have a defined purpose, recipient group and information set. More interest does not automatically justify more disclosure.

Questions to ask before granting access

Before making information public or sharing it with another party, ask:

  1. Do I have authority? Confirm ownership, contractual rights and internal approval to disclose.
  2. Is the disclosure lawful? Consider personal data, confidentiality, court restrictions, regulation and third-party rights.
  3. Is it necessary? Share only what the recipient needs for the current purpose.
  4. Is the recipient appropriate? Verify identity, role, conflicts and professional status where relevant.
  5. Which access level is suitable? Public, selected private access, NDA-controlled access or no disclosure yet.
  6. Should anything be redacted? Remove unrelated personal, confidential and security-sensitive information.
  7. Is an NDA required? Put it in place before disclosure, not afterwards.
  8. Can onward sharing occur? Define permitted advisers, employees and contractors.
  9. How long is access needed? Set a review period and remove access when it ends.
  10. Can I evidence the decision? Record what was shared, the purpose, recipient, authority and date.

Revoking access does not erase earlier disclosure

Removing a recipient's access can prevent future platform access, but it may not delete authorised downloads, screenshots, notes, backups or copies already made outside the platform.

Before enabling download or broad document access, consider whether the recipient needs the complete file. Contractual restrictions, watermarks, view-only access and audit records may reduce risk where available, but none offers an absolute guarantee.

If information was shared with the wrong recipient or exposed unexpectedly, act promptly under the relevant incident, contractual and data-protection procedures. Do not assume that changing the visibility setting alone resolves the event.

Responsibility is shared, but roles differ

The person uploading or sharing information is responsible for deciding whether they have authority to do so, selecting the intended visibility and recipients, reviewing redactions and complying with obligations applying to the source material.

DaDepo is responsible for operating its own services and access controls in accordance with its applicable legal and contractual obligations. A user's sharing choice does not excuse a failure by DaDepo to apply the selected setting correctly, and platform controls do not excuse an unauthorised disclosure by the user.

The applicable Terms, Privacy Policy, data-processing arrangements and specific transaction documents determine the parties' precise responsibilities.

What DaDepo does—and does not do

DaDepo can help organise source documents, present structured information, support selected access and, where available, maintain a record of sharing events and permissions. Users review the information and choose how it may be shared.

Using public, private or NDA-controlled settings does not mean that DaDepo has:

  • confirmed the uploader's ownership or authority to disclose;
  • determined the lawful basis for personal-data sharing;
  • reviewed every confidentiality or third-party restriction;
  • approved an NDA as suitable or enforceable;
  • guaranteed that a recipient will comply with access restrictions;
  • guaranteed that public information will not be copied or indexed;
  • provided legal, privacy, security or transaction advice; or
  • accepted responsibility for a user's unauthorised disclosure.

Important: DaDepo provides technology and information tools. It does not provide legal, data-protection, financial, investment, tax, accounting or security advice. Users should obtain appropriate professional advice before sharing sensitive information or relying on an NDA or access setting.

Share progressively and deliberately

Good disclosure is not measured by the number of documents released. It is measured by whether the right information reaches the right authorised person, for the right purpose, at the right stage and with appropriate safeguards.

Begin with the minimum. Expand access only when the review requires it and the legal, contractual and security conditions are in place.

Further reading